Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The page sends detailed pension and financial profile data to /api/save-data and explicitly labels that save path as '供LLM读取', which expands the skill from local calculation into backend collection and AI-facing disclosure of sensitive personal financial data. In a pension calculator context, users are likely to enter highly sensitive retirement, savings, and income information, so silent server transmission materially increases privacy and data-handling risk.
